ClinicsHive
Privacy Policy
Last updated 12 July 2026
This policy explains what personal data ClinicsHive collects, how we use it, and the choices you have. It works alongside our Terms of Service.
1. Scope — who this policy is for
This Privacy Policy explains how ClinicsHive (“ClinicsHive”, “we”, “us”) handles personal data. It is written mainly for the people who use the Service — clinic Owners, Staff Doctors, and Secretaries.
Two different roles matter here. For the accounts of clinic users, we are the controller of that data. For patient records that a clinic enters into the Service, the clinic is the controller and ClinicsHive is a processor acting on the clinic’s instructions. Section 6 covers patient data specifically.
2. Information we collect
- Account & profile — when you sign in with Google, we receive your name, email address, and profile picture. We do not receive your Google password.
- Clinic information — details you provide about your clinic, such as its name, settings, and working hours.
- Billing information — subscription and payment details are handled by our payment processor. We receive information needed to manage your subscription, but we do not store full card numbers.
- Patient Data— information about patients that a clinic enters into the Service, including any documents or images attached to a patient’s record. This is provided and controlled by the clinic (see section 6).
- Technical & usage data — information generated automatically when you use the Service, such as log data, IP address, device and browser information, and error diagnostics used to keep the Service running reliably.
4. How we use information
We use personal data to:
- provide, operate, and maintain the Service;
- authenticate you and keep accounts secure;
- process subscriptions and payments;
- send you service-related messages (such as notifications, reminders, and billing emails);
- provide support and respond to your requests;
- monitor, debug, and improve the Service; and
- comply with legal obligations and enforce our terms.
We send transactional and service messages, not marketing newsletters. We do not sell personal data.
5. Legal basis
We process personal data where it is necessary to provide the Service to you under our agreement, where we have a legitimate interest in operating and securing the Service, where we have your consent, and where processing is required to meet a legal obligation. We handle personal data in line with applicable Lebanese data-protection law, including Law No. 81/2018 on electronic transactions and personal data.
6. Patient data — the clinic is in control
For patient records, the clinic decides what is collected and how it is used; ClinicsHive only stores and processes that data on the clinic’s behalf to provide the Service.
- The clinic is responsible for informing its own patients about how their data is handled and for having any consent required to collect and store it.
- We do not use patient data for our own purposes, and we do not contact a clinic's patients except where the Service sends messages (such as appointment reminders) on the clinic's behalf.
- A patient who wants to access, correct, or delete their records should contact the clinic that treats them, as the clinic controls those records.
8. International data transfers
The providers we rely on operate infrastructure outside Lebanon. This means your data — including patient data stored by a clinic — may be transferred to, stored, and processed in other countries, whose data-protection laws may differ from Lebanon’s. Where we transfer data internationally, we take steps intended to keep it protected consistent with this policy.
9. Data retention
We keep account data for as long as your account is active and for a reasonable period afterwards. For patient data, retention follows the clinic’s relationship with us: after an Organization is cancelled or terminated, we keep its patient data available for export for 30 days and then permanently delete it, except where we are required to retain limited records by law. Where an account has unpaid fees, export may be withheld until the account is settled, and the 30-day window runs from settlement. This mirrors the termination terms in our Terms of Service.
10. Security
We use commercially reasonable technical and organisational measures to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your Google account and access credentials secure.
11. Your rights
Subject to applicable law, you may request to access, correct, or delete the personal data we hold about you as a user of the Service, and object to or restrict certain processing. To make a request, contact us at support@clinicshive.com.
If your request concerns patient records held by a clinic, please contact that clinic directly, as it controls those records; we will support the clinic in responding.
12. Children’s data
ClinicsHive is used by clinics, which may treat patients who are minors. Where a clinic stores data about a minor patient, the clinic is responsible for having the appropriate legal basis, including any parental or guardian consent required. ClinicsHive does not knowingly collect data directly from children through the Service.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above and, for material changes, take reasonable steps to let you know. Continued use of the Service after changes take effect means you accept the updated policy.
14. Contact
For any questions about this Privacy Policy or how we handle your data, contact us at support@clinicshive.com.
Questions about these terms? Email support@clinicshive.com.